FALSE ALARM: Maya 2016 | Bitfrost

hello.

I´m not sure if this the right section for this topic, but have a big problem. I´m actually really happy with avast, but recently
I installed Maya 2016 (EDU version) on my PC (win 10 x64) and maya had an update. With that update, there was a new plugin
installed called ‘bitfrost’. The issue now is, that avast is always deleting the .dll ´s in the following folder:
C:\Program Files\Autodesk\Maya2016\plug-ins\bifrost\bin

What I did was creating an exception for this folder to not be examined by avast, but it somehow still does it. I restored the .dll´s,
but avast keeps deleting them. I also contacted avast support, no response…

What can I do? The .dll´s are still in the containter, but restoring them right now would be senseless because avast simply would
delete them again.

Help would be awesome, thanks in advance!

Pls Check .dll file on virus Total:https://www.virustotal.com/
And post the virustotal scan result here.Post screenshot of Avast! detection file.

These results make it even morelikely it is a FP: https://www.herdprotect.com/bifrostemp.dll-abc430faa602a259cf37c9aec4ffb95354e4f0fc.aspx
Read here: http://systemexplorer.net/file-database/file/bifrostemp-dll

polonus

Even malwarebytes antimalware showed this program Maya 2016 as false positive. It’s fixed now https://forums.malwarebytes.org/index.php?/topic/167817-false-positive-maya-2016-dll-files/

Also make sure you keep your Maya 2016 up-to-date and all other program up-to-date via Autodesk Application Manager.

Thanks for the replies.
Here´s the virustotal results and screenshot of the autodesk update, with which the bitfrost plugin came.
Exceptions are also in the attachments… completely useless though. Everything EDUCATION versions.
Weird thing is that it says ‘please apply’ the update, but also as state of the update ‘installed’.

Will try to restore the .dll´s again. If that doesn´t work, what else can I do?

Hi,
The file Polonus mentioned (https://www.herdprotect.com/bifrostemp.dll-abc430faa602a259cf37c9aec4ffb95354e4f0fc.aspx) was not detected, but I added it to our cleanset.
I am not sure which file we are talking about though - can you attach the file or give me a hash of it?
Thanks,
Honza

Hi Fai, I too have an autodesk program called Autodesk Navisworks. I installed the 2015 version but I ended up getting the Service Pack 2. I then used the Autodesk Application Manager and it found the Service Pack 3 and I installed it and it got installed successfully.

Thing is we are not talking about just one file. It´s a whole list of .dll´s.
Basically the whole ‘bitfrost’ folder is malware to avast.
And that´s a huge problem and I have no clue what to do.

Ok. Just follow the instructions mentioned by HonzaZ. You can email virus at avast dot com

Put the Subject as false positive and attach the detected files on the email. Make a new folder and put the detected files in that new folder and password protect the file “infected”, without quotes.

Another way u can do is to submit a avast support ticket via here https://support.avast.com/support/tickets/new and click on “I need help using a product”. After you submit your support ticket don’t edit/or make a new reply or else your support ticket will be pushed back in the line. Tickets are handled first come first serve basis.

Yup. You say it is “a list of dlls”, but that does not mean there are actually more detections. If you send me one or two files, I might be able to fix all of them. It is always better to have ALL the files that are detected, so we can make sure they will not be detected in the future.
So to sum it up - we still need the file. You can use our FTP server - https://www.avast.com/faq.php?article=AVKB160 and post the filename(s) here.

Alright, thanks!
Will try to do it asap, but really busy week.
Maybe this weekend!
One more thing: Wouldn´t it be best to just submit the whole bitfrost folder? Since I don´t really know
which files are detected becasue there are always new ones adding up…

Why not, there should be enough space on the server :smiley:
I am notified whenever someone posts in this thread, so feel free to just respond here with the filenames and I will take care of it.

Alright, just uploaded the bitfrost folder in your ‘incoming’ folder. I hope it´s complete.
Tell me if everything is working, did this for the first time.

name: ‘autodesk bitfrost false positive.rar’
operating system: windows 10 x64

Considering that the DLLs you sent are detected as Win32:Bifrost [Susp], and this is Bifrost, I do not think it is a good definition of a false positive :smiley: more like intended behaviour…
I will find out what can be done with this ;).

I mean, all I know is that avast blocks them and makes it unusable :smiley:

True :D.
I already asked some PE analysts about this detection / files, and will let you know the outcome :wink:

Perfect man, thanks a bunch

Will you update here?

Yes I will :wink:

So errrm… I bear mixed news.

  • The detection will remain the same.
  • The files you sent me are definitely not harmful, so I will whitelist them (in a couple of hours nothing should be detected). Keep in mind that whitelist is hash-based, so whenever anyone changes one byte of them, they might be detected again.
  • In case anything gets updated, and Avast starts detecting is again (or just preemptively), I suggest excluding the folder from scanning: https://www.avast.com/en-us/faq.php?article=AVKB168
    Honza